← All stories
● Covered by 1 source · 1 reportLow impact1 negative

Threema secure messaging service disrupted by large-scale DDoS attacks

🔄 Updated 2h ago
New to BrevFeed? We gather this story from every outlet covering it into one summary — ranked by real-world impact, not just the latest headline — so you never miss what matters. What is BrevFeed? →

Key points

  • Threema experienced service disruptions from DDoS attacks.
  • Attacks targeted Threema and its colocation partner, Nine.
  • Threat actor constantly changed attack patterns.
  • Threema On-Prem users were unaffected.

DDoS Attacks Target Threema

The Threema secure messaging service was subjected to multiple distributed denial-of-service (DDoS) attacks earlier this week, leading to significant service interruptions. Users reported issues starting Tuesday evening UTC, with some experiencing delayed messages and connectivity problems. The company initially attributed the problem to a network outage at its colocation partner, but later confirmed it was under a series of DDoS attacks.

Challenges in Mitigation

Threema stated that the attacks were particularly challenging to defend against due to their large scale and the attacker's continuous modification of tactics. The threat actor frequently changed attack patterns, making it difficult for mitigation measures to adapt effectively. The attacks targeted both Threema's infrastructure and that of its colocation partner, Nine.

Impact on Users

The attacks rendered Threema's service temporarily unavailable or only partially available on Tuesday evening and Wednesday morning. While Threema typically mitigates DDoS attacks without noticeable impact, the persistence and evolving nature of these attacks caused intermittent outages for users in various regions, including Switzerland, India, and China. Threema On-Prem users, who operate on their own infrastructure, were not affected by these disruptions.

Company Response

Threema, a Swiss-developed paid messaging application known for its focus on security and privacy, relies on its own server infrastructure in Switzerland. The company issued a post-mortem report detailing the nature of the attacks and the difficulties encountered in mitigating them. It remains unclear whether Threema was the primary target or if the attacks were part of a broader campaign against multiple entities.

✨ This summary was generated by AI from the outlets' reporting listed below. It is not independently verified and may contain errors — check the original sources. How BrevFeed works →

The daily brief

One email each morning: the day's tech stories, clustered across outlets and summarized. No account needed.

One email a day. Unsubscribe in one click, any time.

Today's brief

Spend a few minutes, get the whole day. Every topic's top stories in one hands-free rundown — listen, watch, or read the transcript.

~11 min · 9 stories · Aug 16

▶ Play today's brief Listen on Spotify

New every morning, and the back catalogue is archived by date.

Reporting from

The Threema secure messaging service experienced severe disruptions due to multiple large-scale distributed denial-of-service (DDoS) attacks. The attacks were difficult to mitigate because the threat actor constantly changed patterns and targeted both Threema and its colocation partner. This incident highlights the persistent challenge of defending against sophisticated DDoS campaigns, even for services focused on security.